Task Information
Task ID: b7aabc5b-abf5-11f1-b69f-42010aa4000b
File name: 42a0000.shc
Task parameters: ClamAV scan: True
Unpack: False
Share file: True
ClamAV Results
The file matched the following open source and commercial ClamAV rules.
No matches
YARA Results
Static Analysis
The following YARA rules matched on the file (static analysis).
Rule name: Borland
Alert
Author: malware-lu
TLP: TLP:WHITE
Repository:
Rule name: malware_shellcode_hash
Alert
Author: JPCERT/CC Incident Response Group
Description: detect shellcode api hash value
TLP: TLP:WHITE
Repository: JPCERTCC
Rule name: MD5_Constants
Alert
Author: phoul (@phoul)
Description: Look for MD5 constants
TLP: TLP:WHITE
Repository:
Rule name: RIPEMD160_Constants
Alert
Author: phoul (@phoul)
Description: Look for RIPEMD-160 constants
TLP: TLP:WHITE
Repository:
Rule name: ScanStringsInsocks5systemz
Alert
Author: Byambaa@pubcert.mn
Description: Scans presence of the found strings using the in-house brute force method
TLP: TLP:WHITE
Repository: YARAify
Rule name: SHA1_Constants
Alert
Author: phoul (@phoul)
Description: Look for SHA1 constants
TLP: TLP:WHITE
Repository:
Rule name: without_attachments
Alert
Author: Antonio Sanchez <asanchez@hispasec.com>
Description: Rule to detect the no presence of any attachment
Reference: http://laboratorio.blogs.hispasec.com/
TLP: TLP:WHITE
Rule name: without_urls
Alert
Author: Antonio Sanchez <asanchez@hispasec.com>
Description: Rule to detect the no presence of any url
Reference: http://laboratorio.blogs.hispasec.com/
TLP: TLP:WHITE
Unpacker
The following YARA rules matched on the unpacked file.
Disabled by submitter
Unpacked Files
The following files could be unpacked from this sample.
Disabled by submitter